Impact
n8n versions prior to 1.123.80, 2.39.6, and 2.40.1 contain a validation bypass in the community package installation handler for queue mode deployments. An attacker with write access to Redis can bypass name validation, permission checks, checksum verification, and npm safety checks, enabling the installation of arbitrary npm packages on all cluster instances. This flaw permits attackers to execute arbitrary code with the privileges of the n8n process across the entire cluster, jeopardizing confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects the n8n application from n8n-io. Specifically, all releases before version 1.123.80, before 2.39.6, and before 2.40.1 are susceptible.
Risk and Exploitability
The flaw carries a CVSS score of 7.5 and is not listed in CISA KEV. Exploit probability is unknown due to lack of EPSS data. Attackers must have write access to the Redis instance used by the cluster; from that position they can install arbitrary packages without authentication, leading to remote code execution across all nodes.
OpenCVE Enrichment